Topic · Security

Best bug bounty skills for Claude Code, Codex and other agents.

Skills that structure bug bounty recon, hunting and report writing.
skills
75
official
4

Bug bounty skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Bug bounty skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

awarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT3 days ago
2

Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

awarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT3 days ago
3

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

j3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT2 mo ago
4

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

tanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassUnknown2 mo ago
5

Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

awarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT3 days ago
6

A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

tradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMITtoday
7

Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

samugit83/redamon3k—~1.1kAutomated safety check: PassMITtoday
8

Operates Flounder, an autonomous white-hat security auditor.

adshao/flounder519—~9.2kAutomated safety check: PassAGPL-3.02 days ago
9

Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

PrefectHQ/fastmcp28k—~1.2kAutomated safety check: PassApache-2.0today
10

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

Encod3d-Sec/TORCH3291 repo~1.8kAutomated safety check: PassMIT1 mo ago
11

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

elementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT1 mo ago
12

Structure and per-section format reference for a bug bounty report, aligned with YesWeHack's official guidance.

yeswehack/claude-kit107—~2.1kAutomated safety check: PassGPL-3.01 mo ago
13

Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

Encod3d-Sec/TORCH3291 repo~1.3kAutomated safety check: PassMIT1 mo ago
14

移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。

s7safe/android-h1210—~631Automated safety check: PassNo licence5 mo ago
15

Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
16

HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

Gabson0x/bountyforge443—~1.2kAutomated safety check: PassNo licence21 days ago
17

Self-validates a bug bounty report draft before submission. An agent skill from yeswehack/claude-kit.

yeswehack/claude-kit107—~1kAutomated safety check: PassGPL-3.01 mo ago
18

Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews.

tradecatlabs/vibe-coding-cn17k2 repos~10kAutomated safety check: PassMITtoday
19

Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup.

tradecatlabs/vibe-coding-cn17k2 repos~9.9kAutomated safety check: PassMITtoday
20

Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting.

tradecatlabs/vibe-coding-cn17k2 repos~7.7kAutomated safety check: PassMITtoday
21

Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus.

tradecatlabs/vibe-coding-cn17k2 repos~3.5kAutomated safety check: PassMITtoday
22

Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring.

tradecatlabs/vibe-coding-cn17k2 repos~2.5kAutomated safety check: PassMITtoday
23

Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target.

tradecatlabs/vibe-coding-cn17k2 repos~2.2kAutomated safety check: PassMITtoday
24

Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

bugbountywithmarco/bugbounty-disclosed-reports122—~524Automated safety check: PassNo licence2 mo ago
25

Spawning and hardening scan containers from the recon orchestrator: the security flags that look correct and break the container, and the sibling bind-mount path handling.

samugit83/redamon3k—~1.7kAutomated safety check: PassMITtoday
26

Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

awarexone/Agentic-Bug-Hunter5.3k3 repos~3.4kAutomated safety check: PassMIT3 days ago
27

A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

mtarcure/claude-vibe-squad163—~3.6kAutomated safety check: PassMIT17 days ago
28

Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

bugbountywithmarco/bugbounty-disclosed-reports122—~550Automated safety check: PassNo licence2 mo ago
29

Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.

awarexone/Agentic-Bug-Hunter5.3k2 repos~3.9kAutomated safety check: PassMIT3 days ago
30

Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools

CommonHuman-Lab/nyxstrike157—~639Automated safety check: PassUnknowntoday
31

Changing or adding a project setting / default value in RedAmon.

samugit83/redamon3k—~2.4kAutomated safety check: PassMITtoday
32

Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
33

Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field.

samugit83/redamon3k—~2.2kAutomated safety check: PassMITtoday
34

Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

microsoft/haste107—~1kAutomated safety check: PassMITtoday
35

A skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a…

serejaris/personal-corp-os229—~3.4kAutomated safety check: NotesMITtoday
36

Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.

fabricioctelles/skills106—~2.8kAutomated safety check: PassApache-2.03 days ago
37

Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

bugbountywithmarco/bugbounty-disclosed-reports122—~585Automated safety check: PassNo licence2 mo ago
38

Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

Encod3d-Sec/TORCH329—~611Automated safety check: PassMIT1 mo ago
39

Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently…

samugit83/redamon3k—~1.9kAutomated safety check: PassMITtoday
40

Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.

trailofbits/skills7.4k—~2.2kAutomated safety check: PassCC-BY-SA-4.0today
41

Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation…

provos/ironcurtain613—~6.3kAutomated safety check: PassApache-2.0yesterday
42

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMIT3 days ago
43

Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.

yeswehack/claude-kit107—~4.3kAutomated safety check: WarnGPL-3.01 mo ago
44

Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.

trailofbits/skills7.4k—~996Automated safety check: PassCC-BY-SA-4.0today
45

Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f

CommonHuman-Lab/nyxstrike157—~907Automated safety check: PassUnknowntoday
46

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi

sickn33/agentic-awesome-skills47k1 repo~3.2kAutomated safety check: PassMITtoday
47

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next.

sickn33/agentic-awesome-skills47k1 repo~5.4kAutomated safety check: PassMITtoday
48

Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling…

awarexone/Agentic-Bug-Hunter5.3k—~20kAutomated safety check: WarnMIT3 days ago

Questions, answered from the data.

What is the best bug bounty skill?

Web3 Smart Contract Audit from awarexone/Agentic-Bug-Hunter ranks first of the 75 bug bounty skills listed here, with the highest score: its repository has 5.3k GitHub stars, 3 other GitHub owners carry a copy, its SKILL.md loads about 4.5k tokens and it passes the automated safety check with no findings. Next come Bug Bounty Hunting Methodology and Metabigor OSINT Recon.

Which bug bounty skills are official?

4 of the 75 bug bounty skills are official, published by the vendor's own GitHub organization: Security Analysis, Vulnerability Triage Brocards, Audit Context Building and Auditing Hackerone Vulns.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.